linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Watching over non-existent folder to maintain a generic audit.rules file
@ 2015-07-28 15:26 Florian Crouzat
  2015-07-28 19:23 ` Steve Grubb
  0 siblings, 1 reply; 7+ messages in thread
From: Florian Crouzat @ 2015-07-28 15:26 UTC (permalink / raw)
  To: linux-audit

Hello,

I'm a bit new with auditd so excuse me if this question has been already
answered but I failed to find answers.

I'm in the process of replacing a FIM tool by auditd which is by far
more powerful but I wanted to describe all possibles files and folders
(or system calls) that I need to watch over in a generic audit.rules
files that I would deploy on thousands of hosts.
Unfortunately, I do not only watch over system-related files and folders
but also applicative ones (eg custom path where some private keys are
stored, etc) ..
My problem is that these folders do not exists on all hosts thus making
it impossible to write a generic audit.rules files.
As I said, I have thousands of hosts and I can't imagine deploying
different files on every hosts depending on the profile of the host.
I know puppet could help me for this kind of stuff but I don't have it
yet and even though, it would be difficult to configure.

How do you guys usually workaround this issue ? I'm pretty sure I'm not
the first one wanting to deploy a generic hardening across many hosts
(but maybe I'm the only one using auditd to watch over something else
than pure system-related stuff?

Thanks,
Florian

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2015-08-04 22:26 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-07-28 15:26 Watching over non-existent folder to maintain a generic audit.rules file Florian Crouzat
2015-07-28 19:23 ` Steve Grubb
2015-07-28 22:39   ` Burn Alting
2015-07-29  6:24     ` Florian Crouzat
2015-08-04 13:57       ` Florian Crouzat
2015-08-04 19:55         ` Steve Grubb
2015-08-04 22:26           ` Burn Alting

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).